Authentication Bypass Vulnerability in Backup and Staging by WP Time Capsule
CVE-2026-42760

7.5HIGH

What is CVE-2026-42760?

An authentication bypass vulnerability exists in the Backup and Staging plugin by WP Time Capsule, which enables attackers to exploit password recovery mechanisms. This issue allows unauthorized access to sensitive data, posing a significant security risk. The affected versions include all prior to and including 1.22.25. Users are strongly encouraged to update to the latest version to mitigate the risk associated with this vulnerability.

Affected Version(s)

Backup and Staging by WP Time Capsule 0 <= 1.22.25

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

dodoh4t | Patchstack Bug Bounty Program
.